SOCA Access Control System version 180612 suffers from a cross site request forgery vulnerability.
>> ARCHIVE: 2019-05
During a short security test, SEC Consult found a severe security vulnerability in the clearsign package of supplementary Go cryptography libraries.
This is the systemd-journald exploit produced by Qualys that demonstrates the vulnerabilities as highlighted in CVE-2018-16865 and CVE-2018-16866.
Schneider Electric U.Motion Builder 1.3.4 – ‘track_import_export.php object_id’ Unauthenticated Command Injection
PasteShr 1.6 – Multiple SQL Injection
PHP-Fusion 9.03.00 – ‘Edit Profile’ Remote Code Execution (Metasploit)
Sales ERP 8.1 – Multiple SQL Injection
TwistedBrush Pro Studio 24.06 – ‘.srp’ Denial of Service (PoC)
TwistedBrush Pro Studio 24.06 – ‘Script Recorder’ Denial of Service (PoC)
TwistedBrush Pro Studio 24.06 – ‘Resize Image’ Denial of Service (PoC)